Kubernetes:同集群Pod间HTTPS通信及Apache证书配置方法
Got it, let's break this down into actionable steps for getting your Apache-based Pod2 set up with HTTPS for intra-cluster communication with Pod1 using the internal domain backend-srv.area.cluster.local. I’ll cover both an automated, production-ready approach and a simpler manual method for testing:
Cert-Manager is the de facto tool for managing TLS certificates in Kubernetes—it handles issuance, renewal, and rotation automatically, which is perfect for long-term cluster operations.
Step 1: Install Cert-Manager (if not already present)
You can install it via Helm for simplicity:
helm repo add cert-manager https://charts.jetstack.io helm repo update helm install cert-manager cert-manager/cert-manager --namespace cert-manager --create-namespace --version v1.13.0 --set installCRDs=true # Verify the installation completes successfully kubectl wait --for=condition=available deployment --timeout=600s -n cert-manager cert-manager
Step 2: Create a Self-Signed ClusterIssuer
Since we’re dealing with an internal cluster domain, a self-signed issuer will work perfectly. Create a ClusterIssuer manifest:
apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: name: selfsigned-cluster-issuer spec: selfSigned: {}
Apply it with:
kubectl apply -f cluster-issuer.yaml
Step 3: Request a Certificate for Your Internal Domain
Create a Certificate resource targeting your domain. Make sure the namespace matches where Pod2 is deployed:
apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: backend-srv-cert namespace: area # Match Pod2's namespace spec: secretName: backend-srv-tls # Cert-Manager will store the cert in this Secret issuerRef: name: selfsigned-cluster-issuer kind: ClusterIssuer dnsNames: - backend-srv.area.cluster.local - backend-srv.area.svc.cluster.local # Optional but adds redundancy privateKey: algorithm: RSA size: 2048
Apply it with:
kubectl apply -f backend-cert.yaml
Step 4: Mount the Certificate Secret to Pod2 (Apache)
Update Pod2’s Deployment/StatefulSet to mount the TLS Secret into Apache’s certificate directory. Here’s an example Deployment snippet:
apiVersion: apps/v1 kind: Deployment metadata: name: apache-backend namespace: area spec: replicas: 1 selector: matchLabels: app: backend template: metadata: labels: app: backend spec: containers: - name: apache image: httpd:2.4 ports: - containerPort: 443 volumeMounts: - name: tls-cert mountPath: /usr/local/apache2/conf/ssl/ # Adjust to your Apache cert path readOnly: true - name: apache-ssl-config mountPath: /usr/local/apache2/conf/httpd.conf # Mount custom SSL config readOnly: true volumes: - name: tls-cert secret: secretName: backend-srv-tls # The Secret from Cert-Manager - name: apache-ssl-config configMap: name: apache-ssl-config # We'll create this next
Step 5: Configure Apache to Use HTTPS
Create a ConfigMap with Apache’s SSL-enabled configuration:
apiVersion: v1 kind: ConfigMap metadata: name: apache-ssl-config namespace: area data: httpd.conf: | LoadModule ssl_module modules/mod_ssl.so Listen 443 <VirtualHost *:443> ServerName backend-srv.area.cluster.local SSLEngine on SSLCertificateFile /usr/local/apache2/conf/ssl/tls.crt SSLCertificateKeyFile /usr/local/apache2/conf/ssl/tls.key # Add your existing Apache config (document root, routes, etc.) here DocumentRoot "/usr/local/apache2/htdocs" <Directory "/usr/local/apache2/htdocs"> AllowOverride None Require all granted </Directory> </VirtualHost>
Apply it and restart the Apache deployment to load the new config:
kubectl apply -f apache-config.yaml kubectl rollout restart deployment apache-backend -n area
Step 6: Make Pod1 Trust the Certificate
Since this is a self-signed cert, Pod1 needs to trust its CA. Mount the CA cert (from the same backend-srv-tls Secret) into Pod1’s trusted certificate store. For a Debian/Ubuntu-based Pod1, update its Deployment:
# Add this to Pod1's Deployment spec volumes: - name: trusted-ca secret: secretName: backend-srv-tls items: - key: ca.crt path: backend-ca.crt volumeMounts: - name: trusted-ca mountPath: /usr/local/share/ca-certificates/ readOnly: true # Update the container command to refresh trusted certs on startup command: ["/bin/sh", "-c"] args: ["update-ca-certificates && <your-existing-startup-command>"]
Restart Pod1, and it’ll now trust Pod2’s HTTPS endpoint.
If you don’t want to use Cert-Manager for a quick test, you can generate and mount certificates manually:
Step 1: Generate a Self-Signed Cert Locally
Use openssl to create the cert and key:
openssl req -x509 -newkey rsa:2048 -keyout backend.key -out backend.crt -days 365 -nodes -subj "/CN=backend-srv.area.cluster.local" -addext "subjectAltName=DNS:backend-srv.area.cluster.local,DNS:backend-srv.area.svc.cluster.local"
Step 2: Create a Kubernetes Secret for the Cert
kubectl create secret tls backend-srv-tls -n area --cert=backend.crt --key=backend.key
Step 3: Mount and Configure Apache
Follow steps 4 and 5 from Method 1 to mount the Secret and configure Apache’s SSL.
Step 4: Trust the Cert in Pod1
Same as Method 1’s Step 6—mount the backend.crt (since it’s self-signed, this acts as the CA cert) into Pod1’s trusted store.
Quick Notes
- Ensure your
backend-srvService exposes port 443 for HTTPS traffic. - Cert-Manager will auto-renew certificates before they expire, which is why it’s preferred for production.
- For production, if you need publicly trusted certs (unlikely for internal services), you can configure Cert-Manager to use Let’s Encrypt instead of a self-signed issuer.
内容的提问来源于stack exchange,提问作者mostworld77

